SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5637

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests.

HIGH 7.5EPSS 73.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 73.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
73.06% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-306, CWE-400
Affected
apache/zookeeper · debian/debian linux
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.